mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-28 09:12:08 +00:00
831 B
831 B
CVE-2019-14467
Description
The Social Photo Gallery plugin 1.0 for WordPress allows Remote Code Execution by creating an album and attaching a malicious PHP file in the cover photo album, because the file extension is not checked.
POC
Reference
- http://packetstormsecurity.com/files/155357/WordPress-Social-Photo-Gallery-1.0-Remote-Code-Execution.html
- https://seclists.org/fulldisclosure/2019/Nov/13
- https://wpvulndb.com/vulnerabilities/9952